BISO - Enabling Units IT Security
AstraZeneca
The BISO Enabling Units IT Security serves as the Information Security Officer for the Enabling Units IT organization. This position reports to the AstraZeneca Global Head of Cybersecurity Business Operations. The BISO delivers risk management and security expertise to educate, enable, and empower Enabling Units IT and business stakeholders to safeguard information, platforms, and business-critical systems.The BISO team ensures information security is understood and embedded across enterprise business functions. The team leads security consultants and risk analysts responsible for embedding the security policy framework, industry-standard controls, and secure-by-design initiatives into enterprise SaaS platforms, cloud services, and applications supporting Finance, HR, Global Corporate Affairs, Global Business Services, Legal, and M&A functions.The BISO, is the primary strategic cybersecurity partner to Enabling Units IT, covering enterprise business functions including Finance, HR, Global Corporate Affairs, Global Business Services, Legal, and Mergers & Acquisitions. This customer-facing role represents the CISO by leading cybersecurity engagement, alignment, and delivery of cybersecurity risk and resilience outcomes across enterprise business applications and services.The role provides strategic guidance on cybersecurity risks, priorities, and long-term security posture across enterprise SaaS platforms, cloud services, and applications such as Workday, SAP, Coupa, and Concur. A central focus is balancing business enablement with compliance, data protection, identity governance, vendor assurance, and resilience needs across enterprise functions.This leader directs cybersecurity consulting, risk management, remediation, posture reporting, and data analysis activities tailored to the enterprise SaaS and cloud platforms that underpin financial integrity, employee data protection, legal obligations, M&A activity, and critical business operations.AccountabilitiesAct as the primary strategic partner and security consultant to Enabling Units IT leadership, participating in governance forums that drive risk-based decisions, clear accountability, and visible security outcomes.Lead risk posture and architecture engagement for enterprise SaaS and cloud environments, supporting cybersecurity architects in defining cloud-native security patterns that fit business application needs.Lead security consulting and risk management for enterprise applications such as Workday, SAP, Coupa, and Concur, including identity and access management, data protection, integration security, privileged access governance, and vendor assurance.Ensure security controls support financial controls, SOX compliance, data privacy obligations including GDPR, M&A due diligence requirements, and electronic records/signatures expectations where applicable.Deliver change-controlled security improvements within enterprise applications and cloud services, including documentation expectations, governance alignment, and compensating controls where needed.Drive comprehensive application visibility, security posture reporting, and risk-based vulnerability or exposure management across enterprise SaaS and cloud platforms with continuous update models.Provide security consulting for critical enterprise integrations, including HR-to-Finance, procurement-to-payment, and other cross-functional data flows, ensuring secure patterns, identity controls, logging, and resilience.Strengthen third-party risk management for SaaS providers, cloud platforms, business service providers, and professional services partners, including contractual controls, ongoing assurance, and secure support models.Partner with security operations and business teams to create environment-specific incident response playbooks, tabletop exercises, and recovery readiness for business-critical enterprise applications.Maintain audit-ready security evidence for financial controls, SOX compliance, data privacy audits, Legal and M&A due diligence, and other enterprise assurance needs.Build enterprise-focused risk dashboards and KPIs covering SaaS security posture, identity governance maturity, critical exposure reduction, privileged access governance, vendor assurance, and recovery readiness.Tailor cybersecurity culture and training for Finance, HR, Legal, Global Corporate Affairs, Global Business Services, M&A, and related business users, emphasizing role-appropriate security practices.Coach a high-performing team with clear goals tied to measurable risk reduction, resilience improvement, and business enablement across Enabling Units IT.Essential Skills & Experience Required10+ years of experience in information security positions, including 5+ years overseeing an information security function and influencing senior business and IT stakeholders.Demonstrated experience securing enterprise business applications, SaaS platforms, and cloud services, with the ability to translate business realities into effective cybersecurity controls.Strong familiarity with financial controls and SOX compliance, data privacy regulations including GDPR, electronic records/signatures regulations, and M&A due diligence requirements.Proven ability to design and operationalize cloud-native security patterns for enterprise SaaS platforms and business applications.Hands-on experience securing enterprise SaaS and cloud platforms, including identity and access management, data protection, integration security, privileged access governance, and vendor risk management.Working knowledge of enterprise security frameworks such as NIST CSF, ISO 27001/27002, and CIS Controls, with the ability to apply appropriate controls across business application environments.Experience running risk-based exposure management across enterprise SaaS and cloud platforms that operate under continuous update models.Understanding of global incident response processes with experience adapting containment and recovery approaches to business continuity requirements such as financial close, payroll, procurement, legal workflows, and employee data protection.Experience managing cyber risk across SaaS providers, cloud platforms, business service providers, and professional services partners, including enforceable minimum controls and ongoing assurance.M&A security experience, including cybersecurity due diligence, integration security planning, and post-merger technology risk management, is highly desirable.Demonstrated ability to apply emerging technologies, including AI and automation, to improve cybersecurity and business outcomes while protecting sensitive data and maintaining human oversight.Strong written and verbal communication skills, with the ability to present complex technical information to finance executives, HR leadership, legal counsel, business service leaders, and global IT.Proven ability to manage competing priorities and drive outcomes across enterprise functions with different risk profiles, regulatory obligations, and operational constraints.Executive presence and influence, with the ability to build trusted relationships and guide risk-based decision-making across Enabling Units IT and business leadership.Bachelor's degree in science or relevant technical field of study; Master's preferred. When we put unexpected teams in the same room, we unleash bold thinking with the power to encourage life-changing medicines. In-person working gives us the platform we need to connect, work at pace and challenge perceptions. That's why we work, on average, a minimum of three days per week from the office. But that doesn't mean we're not flexible. We balance the expectation of being in the office while respecting individual flexibility. Join us in our unique and ambitious world.The annual base pay for this position ranges from $190,956.80 - $286,435.20 USD Annual. Hourly and salaried non-exempt employees will also be paid overtime pay when working qualifying overtime hours. Base pay offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. In addition, our positions offer a short-term incentive bonus opportunity; eligibility to participate in our equity-based long-term incentive program (salaried roles), to receive a retirement contribution (hourly roles), and commission payment eligibility (sales roles). Benefits offered included a qualified retirement program [401(k) plan]; paid vacation and holidays; paid leaves; and, health benefits including medical, prescription drug, dental, and vision coverage in accordance with the terms and conditions of the applicable plans. Additional details of participation in these benefit plans will be provided if an employee receives an offer of employment. If hired, employee will be in an “at-will position” and the Company reserves the right to modify base pay (as well as any other discretionary payment or compensation program) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.Date Posted26-Aug-2026Closing Date10-Sept-2026Our mission is to build an inclusive environment where equal employment opportunities are available to all applicants and employees. In furtherance of that mission, we welcome and consider applications from all qualified candidates, regardless of their protected characteristics. If you have a disability or special need that requires accommodation, please complete the corresponding section in the application form.SummaryLocation: US - Gaithersburg - MDType: Full time
- The Commercial IT Cybersecurity Business Information Security Officer (BISO) acts as the main cybersecurity partner to Commercial... ...capabilities stay secure while enabling bold Commercial ambitions?... ...division and associated business units worldwide. Coordinate the security...UnitHourly payFull timeTemporary workWork at officeWorldwideFlexible hours3 days per week
$115k - $125k
...services, fuels our growth, and enables us to support our customers at... ...PurposeThe Lead Information Security Engineer provides senior-level... ...as a key technical advisor to IT leadership and business stakeholders... ...with business units to integrate security controls...UnitCurrently hiringWork at officeRemote work- ...your expertise to impact the IT strategy in a company that follows... ...ROLE:The Director, Cyber Security Detection Engineering is a senior... ...and platform configuration to enable effective threat detection.... ...GSOC, IT, Legal, GRC, business units) with a strong service approach...UnitHourly payFull timeTemporary workWork at officeFlexible hours3 days per week
$110k - $130k
...Saxton Lab Team as a Mid-Level OT/IT Network & Cybersecurity... ...keeping these systems reliable, secure, and ready for research and high... .... Your work directly enables STOL’s connected-vehicle research... ...backhaul to field-deployed roadside units (RSUs), edge nodes, and remote...UnitFull timeLocal areaImmediate startRemote work$113k - $188k
...developers, testers, operations staff, security teams, IV&V partners, helpdesk... ...testing activities, including unit testing, integration testing,... ...Life Cycle (EPLC), federal IT governance, security... ...Experience supporting chatbot, AI-enabled customer support, website updates...UnitFor contractorsFixed term contractFlexible hours- The BISO will serve as the primary strategic cybersecurity partner to the IT Enterprise Technology Services (ETS) organization and its... ...technology services that enable the company’s scientific, manufacturing... ...primary strategic partner and security consultant to ETS leadership,...Hourly payFull timeTemporary workWork at officeLocal areaRemote workFlexible hours3 days per week
$50 per hour
...Casual: FullTimeDepartment: Enterprise Business ServicesBusiness Unit: Enterprise Business ServicesStandard Job DescriptionJoin the... ...Red Team to combine cutting-edge threat intelligence, offensive security operations, and Intelligence Driven Defense principles to set the...UnitFull timeTemporary workWork experience placementCasual workFlexible hours- ...designing, developing, testing, and maintaining secure, scalable enterprise applications that... ...with Enterprise Architecture, DevSecOps, IT Security, QA, Database Administrators,... ...Quality Assurance, and Documentation Develop unit tests, integration tests, and participate...UnitPart timeWork experience placementLocal areaImmediate start
- ...and integrate information from multiple security, intelligence, and operational data sources... ...01, ISO 9001, HDI-certified, woman-owned IT Solutions Provider with strong... ...teams to deliver exceptional performance to enable the safety, security, health, and well-being...Full time
- ...Senior Manager of Application Security The Senior Manager of Application Security will serve as the operational and programmatic leader... .... Provides direction and assistance to other organizational units' policies and procedures, and efficient control and utilization...UnitShift work
$131.3k - $237.35k
...distance to one of the above locations. Leidos is seeking a Cyber Security Architect to join the Air Traffic Business Area within the... ...automation platform built on a hybrid cloud data mesh architecture, enabling next-generation air traffic management capabilities. You will...Full timeRemote work$100k - $120k
...cross-functional development teams to deliver secure, scalable, accessible, and compliant... ...production support in a regulated federal IT environment. Key Responsibilities Appian... ..., and Compliance Develop and support unit, system, integration, regression, performance...UnitFor contractorsWork experience placementLocal areaImmediate start- ...Summary Provides technical strategy and Marketplace security reference architectures, evaluates and enables enterprise security tools/services, designs reusable... ..., or equivalent architecture experience (OPM IT/cyber roles commonly recognize multiple education/experience...Contract workTemporary workFor contractorsFlexible hours
- ...analyzing data from disparate systems and produce cyber insights as necessary to identify, contain, mitigate, and/or recover from cyber security threats and/or incidents. The Cyber Threat Analyst II will work side-by-side with peers to investigate all cyber threats facing...Work experience placementRemote workFlexible hours
- The Senior Security Engineer works under minimal supervision to engineer, administer, and optimize security data pipeline and Zero Trust... ...automation (primarily Python) against the platform's APIs to enable just-in-time access — provisioning entitlements automatically from...Full timeTemporary workFor contractorsFor subcontractorLocal areaImmediate start
$65 - $72 per hour
...Assistance, Inc., (SGA), is searching for a IAM Security Engineer (GCP) for a Contract assignment... ...with external identity providers to enable single sign-on (SSO) and seamless access... ...closely with cross-functional teams, including IT, security, and compliance to align IAM...Full timeContract workRemote work2 days per week3 days per week$90 - $95 per hour
...required Summary: Immediate need for a techno-functional Senior Security Engineer to take the lead on an Optimal ZTA (Zero Trust... ...detection, anomaly detection, and behavior analytics; establish an AI-enabled security tool implementation plan.Create implementation plans with...Permanent employmentContract workImmediate start3 days per week$43.27 - $49.04 per hour
...designing, developing, testing, and maintaining secure, scalable enterprise applications that... ...with Enterprise Architecture, DevSecOps, IT Security, QA, Database Administrators,... ...Assurance, and Documentation\n\n Develop unit tests, integration tests, and participate...UnitPart timeWork experience placementLocal areaImmediate start$176.97k - $303.37k
...management activities across all business lines and operational units. The Chief Compliance Officer also serves as the Bank's Privacy... ...with business leaders, risk management, legal, information security, and audit functions to foster a strong culture of compliance,...UnitWork at officeRemote workFlexible hours$141k - $181k
...mission. Whether it’s architecting critical IT solutions, producing actionable... ...integrate, and evolve cutting-edge systems that enable our customers’ mission. You’ll work alongside... ...to transform mission needs into scalable, secure, and resilient solutions using modern engineering...- ...we collaborate with local clients to fulfill staffing needs in IT, Security, Business Support, and Operations. At Red Key Solutions, we... ...scope and work estimation, architecture and design, coding and unit testing. Primary Responsibilities Participates in and/or...UnitFor subcontractorLocal area
$118.1k - $200.76k
...will assist in conducting internal audits of enterprise IT networks, systems, applications, and security tools to ensure they adhere to Navy and DoD security... ...and maintenance services. Knowing that our work enables the U.S. military and government to recognize, manage...Full timeFor contractorsWork experience placementLocal area$100k - $200k
...transformation enterprise, dedicated to enabling individuals to achieve remarkable feats through... ...with organizational goals. Work with IT experts to identify and implement... ..., technology or related field CompTIA Security+ certification Security clearance ~ You...$175k - $225k
...govern, and optimize cloud infrastructure at scale.The Director of IT, Security & Compliance serves as the senior leader responsible for... ...to strengthen security posture, maintain compliance, drive AI-enabled efficiencies, optimize technology investments, and ensure employees...Remote work$150k - $190k
We are seeking a highly skilled Senior Cybersecurity Analyst / Information Security Manager with expertise in IT security, risk management, and policy development. The ideal candidate will have a minimum of five (5) years of experience implementing security measures to...Full timeContract workPart time- ...systems across Java, JavaScript, Python in a DevOps environment. You will work on security-focused software, cloud environments, and customer tools, contributing to architecture, coding, and unit testing. Candidates should have 8+ years in engineering with Java/Angular/...Unit
$135k - $170k
...solve challenges and celebrate success! Job Summary Under IT Security, the staff shall operate, maintain, and enhance NICHD’s... ...delight our clients Innovation: Embrace creative thinking to enable continual growth and powerful solutions Accountability: Take...Full timeContract workTemporary workLocal area- ...Description: Hybrid 3 days onsite / 2 days remote in either Rockville, MD or Tysons Corner, VA Our client seeks a Security Engineer responsible for designing, implementing, and maintaining controls that protect enterprise systems and data from unauthorized access...Hourly payTemporary workLocal areaRemote work
$150k - $190k
...integration and end-to-end system implementation of mission IT applications, meeting system security policies, operational requirements, and performance... ..., and program execution, you will play a key role in enabling the successful deployment of secure, high-assurance IT...Full timeFor contractorsWork at office$75k - $80k
...Description Job Description Cloud Network Security Engineer Bethesda, MD Must be a US... ...system integration across platforms, API enablement, and compliance with agency and federal... ...DNS requests for public websites and IT resources (IPAM, Infoblox) Interface with...Flexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to BISO - Enabling Units IT Security. Be the first to apply!


